ISO/IEC 27001:2022

View as Markdown

What is ISO 27001?

ISO/IEC 27001:2022 sets requirements for establishing, implementing, maintaining, and continually improving an information security management system. The International Organization for Standardization and the International Electrotechnical Commission publish this globally recognized standard. The 2022 revision of ISO 27001 organizes controls into four categories: Organizational, People, Physical, and Technical.

Who is the intended audience?

ISO/IEC 27001:2022 is for organizations of any size, in any industry, that want a framework for measuring and improving their information security program. Formal ISO/IEC 27001 certification is an industry-recognized way to show your organization’s commitment to information security best practices.

Where can I find more information?

More information on ISO/IEC 27001:2022 is on the ISO website.

How can runZero help me with these controls?

runZero helps most with the Organizational and Technical controls of ISO/IEC 27001:2022. The tables below describe how runZero supports each relevant control.

Organizational controls

No. Control runZero capability
5.9 Inventory of information and other associated assets runZero inventories assets through active scanning, passive discovery, and API integrations, with detailed fingerprinting of IT, OT, and IoT devices across on-prem, cloud, and remote environments. (Playbook)

Technical controls

No. Control runZero capability
8.1 User endpoint devices Through active scanning, passive sampling, and API integrations, runZero can find gaps in user endpoint device controls, including:
  • Devices running end-of-life operating systems
  • Devices missing endpoint protection software
  • Devices missing mobile device management software
  • Endpoints not configured with full disk encryption
  • Use of unauthorized software and services
  • 8.7 Protection against malware Through integrations with endpoint protection platforms, runZero can discover:
  • Devices missing endpoint protection software (Playbook)
  • Devices running out-of-date endpoint protection software
  • Quarantined devices
  • The health status of endpoint protection software
  • 8.8 Management of technical vulnerabilities Through active scanning, passive sampling, and API integrations, runZero supports technical vulnerability management, including:
  • Discovery of vulnerabilities in assets and services through active scanning and passive sampling
  • Integration with vulnerability management platforms such as Qualys, Rapid7, and Tenable
  • Integration with external attack surface management platforms such as Censys and Shodan
  • Discovery of gaps in vulnerability scanning strategy (Playbook)
  • Custom risk and criticality attributes on each asset
  • Custom query-based vulnerability records
  • Custom CVSS scoring in query-based vulnerability records
  • Common Platform Enumeration (CPE) standards for operating system identification
  • Common Vulnerabilities and Exposures (CVE) standards for vulnerability identification
  • 8.9 Configuration management Using active scanning and passive sampling, runZero can monitor configuration baselines by discovering:
  • Devices running end-of-life operating systems and firmware versions
  • Devices running unauthorized or out-of-date software
  • Use of insecure protocols such as telnet, ftp, http, and ssl
  • Use of insecure encryption ciphers such as RC4, DES, and 3DES
  • Network services running on non-standard ports
  • Network services not configured to use authentication and encryption
  • 8.20 Network security runZero can discover and fingerprint both managed and unmanaged network devices through active scanning and passive sampling. With service probing, runZero can also identify weak security configurations and vulnerable firmware versions.
    8.21 Security of network services Using active scanning and passive sampling, runZero can discover network services and their risks, including:
  • Unauthorized network services
  • Non-standard or insecure protocols
  • Weak or unauthorized encryption ciphers
  • Network services that don’t support authentication and encryption
  • Use of legacy SNMP protocols and default community strings (Playbook)
  • 8.22 Segregation of networks To test network segmentation, place an Explorer outside a security zone and scan into it; the results show which assets and services are exposed. runZero can also identify multi-homed assets and potential network bridges.
    8.24 Use of cryptography runZero supports cryptography and key management best practices by discovering:
  • Network services not configured to use encryption
  • Supported versions for protocols such as LDAP, SMB, and SSL/TLS
  • Supported ciphers for protocols such as LDAP, RDP, SMB, SSL/TLS, and SSH
  • Use of shared SSH server host keys
  • X.509 certificates that are expired or nearing expiration
  • Additional runZero resources

    Updated